Vulnerability index

Browse CVEs

2,849 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
CRITICAL 9.1 CVE-2022-40842 ndk design NdkAdvancedCustomizationFields 3.5.0 is vulnerable to Server-side request forgery (SSRF) via rotateimg.php. Ndkadvancedcustomizationfields after 3.5.0 Fix from $2,3002022-11-22 MEDIUM 6.5 CVE-2022-4096 Server-Side Request Forgery (SSRF) in GitHub repository appsmithorg/appsmith prior to 1.8.2. Appsmith 1.8.2+ Fix from $1,6002022-11-21 HIGH 8.8 CVE-2022-41609 Auth. (subscriber+) Server-Side Request Forgery (SSRF) vulnerability in Better Messages plugin 1.9.10.68 on WordPress. Better Messages 1.9.10.69+ Fix from $1,9502022-11-19 HIGH 8.8 CVE-2022-43183 XXL-Job before v2.3.1 contains a Server-Side Request Forgery (SSRF) via the component /admin/controller/JobLogController.java. Xxl Job after 2.3.1 Fix from $1,9502022-11-17 HIGH 7.5 CVE-2022-42894 A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). An unauthenticated Server-Side Request Forgery (SSRF) vulnerabilit… Syngo Dynamics Cardiovascular Imaging And Information System Mitigation only Fix from $1,9502022-11-17 HIGH 7.5 CVE-2022-43140 kkFileView v4.1.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component cn.keking.web.controller.OnlinePreviewController#g… Kkfileview No fix yet Fix from $1,9502022-11-17 MEDIUM 6.5 CVE-2022-39383 KubeVela is an open source application delivery platform. Users using the VelaUX APIServer could be affected by this vulnerability. When using Helm C… Kubevela 1.5.9 / 1.6.2+ Fix from $1,6002022-11-16 HIGH 8.7 CVE-2022-41906 OpenSearch Notifications is a notifications plugin for OpenSearch that enables other plugins to send notifications via Email, Slack, Amazon Chime, Cu… Opensearch Notifications 2.2.1.0+ Fix from $1,9502022-11-11 MEDIUM 6.5 CVE-2022-42494 Server Side Request Forgery (SSRF) vulnerability in All in One SEO Pro plugin <= 4.2.5.1 on WordPress. All In One Seo after 4.2.5.1 Fix from $1,6002022-11-08 MEDIUM 6.5 CVE-2022-20951 A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot application could allow an authenticated, remote attacker to perf… Broadworks Messaging Server 23.0+ Fix from $1,6002022-11-04 HIGH 8.8 CVE-2022-20958 A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot application could allow an unauthenticated, remote attacker to pe… Broadworks Commpilot Application 23.0+ Fix from $1,9502022-11-04 MEDIUM 5.3 CVE-2022-39276 GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that provides ITIL Service Desk feat… Glpi 10.0.4+ Fix from $1,6002022-11-03 CRITICAL 9.8 CVE-2022-41552 Server-Side Request Forgery (SSRF) vulnerability in Hitachi Infrastructure Analytics Advisor on Linux (Data Center Analytics, Analytics probe compone… Infrastructure Analytics Advisor 10.9.0-00+ Fix from $2,3002022-11-01 CRITICAL 9.8 CVE-2022-40296 The application was vulnerable to a Server-Side Request Forgery attacks, allowing the backend server to interact with unexpected endpoints, potential… Php Point Of Sale Mitigation only Fix from $2,3002022-10-31 HIGH 8.1 CVE-2022-3708 The Web Stories plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including 1.24.0 due to insufficient validat… Web Stories 1.25.0+ Fix from $1,9502022-10-28 MEDIUM 6.5 CVE-2022-43776 The url parameter of the /api/geojson endpoint in Metabase versions <44.5 can be used to perform Server Side Request Forgery attacks. Previously impl… Metabase 0.44.5+ Fix from $1,6002022-10-26 HIGH 8.8 CVE-2022-36451 A vulnerability in the MiCollab Client server component of Mitel MiCollab through 9.5.0.101 could allow an authenticated attacker to conduct a Server… Micollab after 9.5.0.101 Fix from $1,9502022-10-25 HIGH 7.5 CVE-2022-41704 A vulnerability in Batik of Apache XML Graphics allows an attacker to run untrusted Java code from an SVG. This issue affects Apache XML Graphics pri… Batik 1.16+ Fix from $1,9502022-10-25 HIGH 7.5 CVE-2022-42890 A vulnerability in Batik of Apache XML Graphics allows an attacker to run Java code from untrusted SVG via JavaScript. This issue affects Apache XML … Batik 1.16+ Fix from $1,9502022-10-25 MEDIUM 6.5 CVE-2022-3247 The Blog2Social: Social Media Auto Post & Scheduler WordPress plugin before 6.9.10 does not have authorisation in an AJAX action, and does not ensure… Blog2social 6.9.10+ Fix from $1,6002022-10-25 CRITICAL 9.8 CVE-2022-38580EPSS 11% Zalando Skipper v0.13.236 is vulnerable to Server-Side Request Forgery (SSRF). Skipper 0.13.237+ Fix from $2,3002022-10-25 MEDIUM 5.3 CVE-2022-39055 RAVA certificate validation system has inadequate filtering for URL parameter. An unauthenticated remote attacker can perform SSRF attack to discover… Rava Certificate Validation System Mitigation only Fix from $1,6002022-10-18 CRITICAL 9.8 CVE-2022-42149 kkFileView 4.0 is vulnerable to Server-side request forgery (SSRF) via controller\OnlinePreviewController.java. Kkfileview Mitigation only Fix from $2,3002022-10-17 CRITICAL 9.1 CVE-2022-41477 A security issue was discovered in WeBid <=1.2.2. A Server-Side Request Forgery (SSRF) vulnerability in the admin/theme.php file allows remote attack… Webid after 1.2.2 Fix from $2,3002022-10-14 CRITICAL 9.8 CVE-2022-41496 iCMS v7.0.16 was discovered to contain a Server-Side Request Forgery (SSRF) via the url parameter at admincp.php. Icms No fix yet Fix from $2,3002022-10-13 CRITICAL 9.8 CVE-2022-41497 ClipperCMS 1.3.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the pkg_url parameter at /manager/index.php. Clippercms No fix yet Fix from $2,3002022-10-13 CRITICAL 9.8 CVE-2022-41495 ClipperCMS 1.3.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the rss_url_news parameter at /manager/index.php. Clippercms No fix yet Fix from $2,3002022-10-13 MEDIUM 6.5 CVE-2022-36551EPSS 5% A Server Side Request Forgery (SSRF) in the Data Import module in Heartex - Label Studio Community Edition versions 1.5.0 and earlier allows an authe… Label Studio after 1.5.0 Fix from $1,6002022-10-03 HIGH 8.8 CVE-2022-41040 KEVEPSS 100% Microsoft Exchange Server Elevation of Privilege Vulnerability Exchange Server Patch available Fix from $1,9502022-10-03 MEDIUM 6.5 CVE-2022-35282 IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to server-side request forgery (SSRF). By sending a specially crafted request, … Websphere Application Server 7.0.0.45 / 8.0.0.15+ Fix from $1,6002022-09-28